CVE-2024-24552: Bludit

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into authorizing a session ID of their choosing.

Affected products

  • Bludit Bludit: from 3.14.0, up to and including 3.15.0

Published 2024-06-24. Last modified 2026-06-17.